logo

Scratching the Surface of Rhysida Ransomware

ID: c094d726-511b-5a9c-a19f-1c6ba7b49b6b

STIX ID: report--c094d726-511b-5a9c-a19f-1c6ba7b49b6b

Feed Name: WatchGuard Secplicity Blog

Threat Score
70/100

Date Published: 2023-05-23

Date Updated: 2026-05-01

Author: The Editor

...
...

This report analyzes an early-stage Rhysida ransomware sample: unpacked MinGW-built binary (~1.2MB) that uses ChaCha20 for file encryption with AES/CHC constructs and RSA-4096-OAEP to encrypt keys, appends the .rhysida extension, drops a PDF ransom note (CriticalBreachDetected.pdf) and exposes a TOR extortion portal (no victims observed). It documents command-line options, self-deletion via PowerShell, files/directories excluded from encryption, and provides file hashes and behavioral details useful for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.